CVE-2019-3648

A Privilege Escalation vulnerability in the Microsoft Windows client in McAfee Total Protection 16.0.R22 and earlier allows administrators to execute arbitrary code via carefully placing malicious files in specific locations protected by administrator permission.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:mcafee:anti-virus_plus:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:internet_security:*:*:*:*:*:*:*:*
cpe:2.3:a:mcafee:total_protection:*:*:*:*:*:*:*:*

History

21 Nov 2024, 04:42

Type Values Removed Values Added
CVSS v2 : 7.2
v3 : 6.7
v2 : 7.2
v3 : 6.1
References () https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648 - () https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648 -
References () https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102984 - () https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102984 -

07 Nov 2023, 03:10

Type Values Removed Values Added
References (CONFIRM) https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102984 - Vendor Advisory () https://service.mcafee.com/webcenter/portal/cp/home/articleview?articleId=TS102984 -
References (MISC) https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648 - Exploit, Third Party Advisory () https://safebreach.com/Post/McAfee-All-Editions-MTP-AVP-MIS-Self-Defense-Bypass-and-Potential-Usages-CVE-2019-3648 -

Information

Published : 2019-11-13 09:15

Updated : 2024-11-21 04:42


NVD link : CVE-2019-3648

Mitre link : CVE-2019-3648

CVE.ORG link : CVE-2019-3648


JSON object : View

Products Affected

mcafee

  • total_protection
  • internet_security
  • anti-virus_plus
CWE
CWE-426

Untrusted Search Path